Malicious PDF — malware analysis report

Static analysis result for SHA-256 06d0c1d4f87bf063…

MALICIOUS

PDF

81.7 KB Created: 2020-08-10 20:48:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bbf531797c6bbb2f2da68a118448a0ce SHA-1: 7a78e25caded517c183cf3cefabd035d2d98e47f SHA-256: 06d0c1d4f87bf063917f04a471af7706fb6fec5ba55b28bfb0ca246ed78e8fcd
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains embedded links, with one critical heuristic firing indicating it points to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains text that appears to be a lure for 'Aristóteles livros pdf'. The presence of numerous external PDF links, many pointing to Shopify, suggests a link farm or SEO manipulation tactic to distribute malicious content. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=arist%25C3%25B3teles+livros+pdf
    • http://files.islamandfeminism.org/uploads/1/3/1/0/131070331/wesixewexuri.pdf
    • http://files.ohioedtech.com/uploads/1/3/1/3/131379716/kiluzuxenobu_xakizemu.pdf
    • http://files.tenescakes.com/uploads/1/3/1/3/131384442/metiz.pdf
    • http://files.japanesephilately.com/uploads/1/3/2/6/132695734/jenezutufo_lexiga_sabaxidado_manovus.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/8538/9206/files/le_journal_d_aurlie_laflamme_tome_1_pdf_gratuit.pdf
    • https://cdn.shopify.com/s/files/1/0434/6390/1336/files/webijinedixuzajulekogizo.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/81579197248.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/21659337375.pdf
    • https://cdn.shopify.com/s/files/1/0430/9313/1425/files/32903127892.pdf
    • https://cdn.shopify.com/s/files/1/0431/8960/0414/files/epigenetics_lyle_armstrong_download.pdf
    • https://cdn.shopify.com/s/files/1/0428/2620/3302/files/67782431955.pdf
    • https://cdn.shopify.com/s/files/1/0431/5666/8565/files/materi_sistem_bilangan_real.pdf
    • https://cdn.shopify.com/s/files/1/0427/8580/0358/files/xolikon.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f0c2.bin
49c579ad8a3c142f8b059dafb51905558e0545b38250a619acfb9780e45f11e2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0C2 5012 bytes
font_01_sfnt_off0001019b.bin
337d6416420a05dbdd303242054fb0b81607403aa080aa24d751cc4156ccb357
pdf-font-stream PDF embedded font (sfnt) at offset 0x1019B 2236 bytes
font_02_sfnt_off00010bb6.bin
de9cef23fadbd661bc0ad643a97ac303e07bf7f6a7c9bdcf6e285a924f65f2b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x10BB6 14356 bytes